Official agent skill

Schema Coverage

by elastic in elastic/terraform-provider-elasticstack

Analyzes a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs + assertions).

OfficialApache-2.0Auto-check passedTesting & QA

Install Schema Coverage

skills CLI
$ npx skills add elastic/terraform-provider-elasticstack --skill schema-coverage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/terraform-provider-elasticstack schema-coverage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/terraform-provider-elasticstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/schema-coverage .claude/skills/schema-coverage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
schema-coverage
GitHub stars
210
Token cost
~1.4k tokens
SKILL.md length
517 words
Files
2
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyzes a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs + assertions).

  • Works in 4 steps: Locate and parse the schema → Locate acceptance tests and collect… → Build a coverage matrix → …
  • The user asks about schema coverage
  • SKILL.md covers Goal, Inputs (infer if not provided), Workflow and Report template, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Schema Coverage is an agent skill from elastic/terraform-provider-elasticstack, published by the product's own GitHub organization. Analyzes a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs + assertions). Produces a prioritized report of missing and poor coverage (set-only assertions, single-value coverage, missing unset/empty cases, missing update coverage). Use when the user asks about schema coverage, test coverage gaps, or improving Terraform acceptance tests for a resource.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).

It sits in Testing & QA, covering End-to-end testing, Infrastructure as code and Test coverage. It works with Terraform and Elasticsearch. The repository describes itself as: Terraform provider for Elastic Stack. The licence is Apache-2.0.

When your agent uses it

  • The user asks about schema coverage
  • Test coverage gaps
  • Improving Terraform acceptance tests for a resource

Example prompts

  • “Use the schema-coverage skill to analyz a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs +…”
  • “/schema-coverage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Locate and parse the schema
  2. Locate acceptance tests and collect attribute usage
  3. Build a coverage matrix
  4. Produce the report (strict ordering)

What it can do on your machine

Read from SKILL.md and the folder at commit 2a6096e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Schema Coverage loads about 1.4k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 517 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/terraform-provider-elasticstack at commit 2a6096e, republished under its Apache-2.0 licence (© elastic). 517 words, ~1,443 tokens.

Download SKILL.mdSave it as .claude/skills/schema-coverage/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
schema-coverage
description
Analyzes a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs + assertions). Produces a prioritized report of missing and poor coverage (set-only assertions, single-value coverage, missing unset/empty cases, missing update coverage). Use when the user asks about schema coverage, test coverage gaps, or improving Terraform acceptance tests for a resource.

Schema Coverage (Terraform resource vs acceptance tests)

Goal

Given a Terraform resource, compare its schema attributes/blocks to what the acceptance tests configure and assert, then highlight opportunities to improve coverage.

Report findings in this order:

  1. Attributes with no coverage
  2. Attributes with poor coverage

Inputs (infer if not provided)

  • Resource name (e.g. elasticstack_elasticsearch_security_api_key)
  • Or the schema file / acceptance test file path
  • Or the Go package directory containing the resource and *_acc_test.go

If the user has an acceptance test open, infer the resource under test from:

  • resource.Test(...) names like resourceName := "elasticstack_..."
  • resource.ParallelTest(...) steps referencing a single resource
  • config builder function names like testAcc...Resource...

Workflow

1) Locate and parse the schema

Find the resource schema definition and capture all schema keys:

  • Top-level attributes in Schema: map[string]*schema.Schema{ ... }
  • Nested block schemas in:
    • Elem: &schema.Resource{ Schema: ... }
    • lists/sets/maps of resources and objects
    • nested blocks referenced via helpers

For each attribute/block, record:

  • Path: terraform attribute path (top-level foo, nested block.0.bar, etc.)
  • Schema metadata: Required/Optional/Computed, ForceNew, type (TypeString, TypeList, etc.), MaxItems/MinItems
2) Locate acceptance tests and collect attribute usage

Scan the acceptance tests for two independent signals:

  • Configured attributes: attributes explicitly set in HCL test configs (including nested blocks).
  • Asserted attributes: attributes referenced in checks, including:
    • value assertions (e.g. TestCheckResourceAttr)
    • set-only assertions (e.g. TestCheckResourceAttrSet)
    • absence assertions (e.g. TestCheckNoResourceAttr)
    • collection assertions (e.g. type-set element checks, list length checks)

Also detect update coverage by identifying multiple resource.TestStep{ Config: ... } steps for the same resource and whether attribute values change between steps.

3) Build a coverage matrix

For each schema attribute path, compute:

  • Configured? (ever set in any test config)
  • Asserted? (ever referenced by any check)
  • Assertion quality:
    • value-specific: asserts the exact value (preferred)
    • set-only: only checks “is set” (weaker)
    • absence: checks unset / removed (good for optional fields)
  • Value diversity: count distinct values across steps/configs (e.g. name="a" vs name="b")
  • Optional-unset coverage: optional field has a test step where it is deliberately omitted, plus an assertion that it is absent (or defaults appropriately)
  • Empty-collection coverage: collection has a step where it is empty (or omitted if optional), plus assertions validating the empty state
  • Update coverage: attribute value changes across steps, and a post-update assertion verifies the new value
Show full SKILL.md (161 more words)Show less
4) Produce the report (strict ordering)

Use the template below.

Report template

markdown
## Schema coverage report: <resource>

### Scope
- **Schema**: <file(s) or function(s)>
- **Acceptance tests**: <test file(s)>

### 1) Attributes with no coverage
These schema attributes/blocks are not referenced in acceptance tests (neither configured nor asserted):
- `<attr_path>`: <Required/Optional/Computed>, <type>. **Gap**: not configured, not asserted.

### 2) Attributes with poor coverage
These attributes appear in tests but the coverage is weak:
- `<attr_path>`: <schema flags/type>
  - **Observed**: <how it’s currently used (configured/asserted), example values>
  - **Gaps**:
    - <one or more of: set-only assertion, single value only, no unset coverage, no empty collection coverage, no update coverage>
  - **Suggested improvements**:
    - <concrete test step or assertion to add>

### Suggested next steps (smallest diffs first)
1. Add value-specific assertions for set-only checks
2. Add an “unset optional” step + `TestCheckNoResourceAttr`
3. Add an “empty collection” step + collection assertions
4. Add an “update” step changing the attribute + post-update assertions

Rules of thumb (for prioritization)

  • Prefer value-specific assertions over “is set”.
  • For Optional attributes, include at least one step where the attribute is omitted, and assert absence/default behavior.
  • For collections (list/set/map), add a case for empty (or omitted if optional), and assert the expected empty state.
  • For Update behavior, ensure there is at least one multi-step test where the attribute changes and the test asserts the new state.
  • For Computed-only attributes, it’s acceptable to use set-only assertions when exact values are not deterministic, but prefer deterministic assertions when possible.

Notes / limitations

  • Some schemas are built via helpers; follow helper references until all attribute keys are accounted for.
  • Attribute paths in checks often use block.0.attr indexing; normalize consistently when matching to schema blocks.
  • Don’t mark an attribute as “covered” solely because it appears in raw HCL—prefer it being asserted. Treat “configured but never asserted” as poor coverage, not good coverage.

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/schema-coverage of elastic/terraform-provider-elasticstack.

  • SKILL.md
  • reference.md

Open the folder on GitHubat commit 2a6096e

Compare with similar skills

Schema Coverage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Schema Coverage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Schema Coverage this skillelastic/terraform-provider-elasticstack210—~1.4kAutomated safety check: PassApache-2.0
Avm Tf TestingAzure/terraform-azurerm-avm-ptn-alz135—~1.8kAutomated safety check: PassMIT
Test Fix WorkflowGoogleCloudPlatform/magic-modules973—~1.3kAutomated safety check: PassCustom licence
New Feature Designagentic-community/mcp-gateway-registry962—~18kAutomated safety check: NotesApache-2.0
Test Failure Decision TreeGoogleCloudPlatform/magic-modules973—~4.2kAutomated safety check: PassCustom licence
Test Monitor WorkflowGoogleCloudPlatform/magic-modules973—~1kAutomated safety check: PassCustom licence

Similar skills

  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Test Fix Workflow

    GoogleCloudPlatform/magic-modules

    Workflow for diagnosing, fixing, and verifying failing Terraform acceptance tests from GitHub issue URLs (detecting test-failure labels), direct prompts, or log files using Failure Scenario Decision…

    973 GitHub stars~1.3k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • New Feature Design

    agentic-community/mcp-gateway-registry

    Design and document new features with GitHub issue, low-level design (LLD), expert review, and testing plan.

    962 GitHub stars~18k tokensUpdated yesterday
    Testing & QAAuto-check: notes
  • Test Failure Decision Tree

    GoogleCloudPlatform/magic-modules

    Classification decision tree and remediation strategies for diagnosing Terraform acceptance test failures across all workflows.

    973 GitHub stars~4.2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Test Monitor Workflow

    GoogleCloudPlatform/magic-modules

    Workflow for fetching, triaging, analyzing, and reporting on nightly acceptance test results across Beta and GA Google Cloud Terraform providers.

    973 GitHub stars~1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Smt E2E Dataflow Debugging

    GoogleCloudPlatform/DataflowTemplates

    Debugs logical errors and data discrepancies in Dataflow templates by launching jobs via Terraform and comparing source (e.g.

    1.3k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed

More from elastic/terraform-provider-elasticstack

All 21 skills in this repo
  • Openspec Explore

    elastic/terraform-provider-elasticstack

    Official

    Enter explore mode - a thinking partner for exploring ideas, investigating problems, and clarifying requirements.

    210 GitHub starsUsed in 86 repos~4.6k tokens
    Auto-check passed
  • Openspec Apply Change

    elastic/terraform-provider-elasticstack

    Official

    Implement tasks from an OpenSpec change. An agent skill from elastic/terraform-provider-elasticstack.

    210 GitHub starsUsed in 91 repos~2.1k tokens
    Auto-check passed
  • Openspec Archive Change

    elastic/terraform-provider-elasticstack

    Official

    Archive a completed change in the experimental workflow. An agent skill from elastic/terraform-provider-elasticstack.

    210 GitHub starsUsed in 85 repos~2.7k tokens
    Auto-check passed
  • PR Monitoring Loop

    elastic/terraform-provider-elasticstack

    Official

    Monitor GitHub pull requests through a subagent-based loop that watches CI checks, review comments, PR comments, review state, merge conflicts, and branch freshness.

    210 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Openspec Plus Proposal

    elastic/terraform-provider-elasticstack

    Official

    MANDATORY skill that activates whenever the OpenSpec proposal phase begins.

    210 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Openspec Propose

    elastic/terraform-provider-elasticstack

    Official

    Propose a new change with all artifacts generated in one step.

    210 GitHub starsUsed in 77 repos~3.1k tokens
    Auto-check passed

Questions about Schema Coverage

What does Schema Coverage do?

Analyzes a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs + assertions). Schema Coverage is an agent skill from elastic/terraform-provider-elasticstack, published by the product's own GitHub organization. Analyzes a Terraform resource schema and compares it to attributes used in the acceptance test suite (configs + assertions).

When should I use Schema Coverage?

Schema Coverage fits situations like: the user asks about schema coverage; test coverage gaps; improving Terraform acceptance tests for a resource.

How do I install Schema Coverage in Claude Code?

Run `npx skills add elastic/terraform-provider-elasticstack --skill schema-coverage -a claude-code`. Or copy the skill folder (.agents/skills/schema-coverage in elastic/terraform-provider-elasticstack) into .claude/skills/schema-coverage in your project. Claude Code loads it when a task matches its description.

How do I install Schema Coverage in Codex?

Run `npx skills add elastic/terraform-provider-elasticstack --skill schema-coverage -a codex`. Or copy the skill folder (.agents/skills/schema-coverage in elastic/terraform-provider-elasticstack) into .agents/skills/schema-coverage in your project. Codex loads it when a task matches its description.

Can I use Schema Coverage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/terraform-provider-elasticstack --skill schema-coverage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/schema-coverage, .gemini/skills/schema-coverage, .github/skills/schema-coverage and .opencode/skills/schema-coverage in your project.

What does Schema Coverage need to run?

SKILL.md names no scripts, command-line tools or credentials: Schema Coverage is instructions for the agent only.

Does Schema Coverage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Schema Coverage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Schema Coverage use?

Schema Coverage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Schema Coverage use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Schema Coverage?

Skills that share tags, products or a category with Schema Coverage: Avm Tf Testing (Azure/terraform-azurerm-avm-ptn-alz, 135 stars), Test Fix Workflow (GoogleCloudPlatform/magic-modules, 973 stars), New Feature Design (agentic-community/mcp-gateway-registry, 962 stars) and Test Failure Decision Tree (GoogleCloudPlatform/magic-modules, 973 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Schema Coverage?

elastic (a GitHub organization, an official publisher) maintains it in elastic/terraform-provider-elasticstack, which has 210 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/terraform-provider-elasticstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.